Time/Place

Attendees

Agenda

  1. Collect stakeholder feedback on Sprint 1
    1. UMD Stakeholder Feedback on Phase 1
    2. Can we involve stakeholders during the sprint?
  2. What Phase1 requirements must be addressed in Sprint 2?
    1. Previously defined Phase 1 requirements
    2. Additional and restated requirements below
  3. Schedule Sprint 2 planning meeting: Oct 26

Candidate Sprint 2 Requirements

  1. Enforce ACLs on ACL resources with filesystem-based backstop
  2. Add ACL uris to response headers as "Link: <acl-uri>; rel=acl"
  3. Implement acl:Control, acl:Append, and acl:Delete modes
  4. F4 MUST provide a way for external services such as Solr to enforce the authorization rules defined in the repository
  5. Enforce ACLs on binary files
  6. More documentation
  7. Support external ACLs (ACLs not managed by fedora)
  8. Add support for agentClass graphs defined within F4
  9. Add support for agentClass graphs defined external to F4
  10. Verify header-based (delegated) authentication is supported (where headers are used to define the effective agent, independent of any container-based AuthN)
  11. Support for inclusion of other ACLs via acl:include
  12. Fix bug with versioned resources: 
  13. Make webac and audit default configuration in fcrepo-webapp-plus: 

Related Documents

Minutes

Collect stakeholder feedback on Sprint 1

  1. Suggestion: Include stakeholders during sprint-2 to help work through issues with sprint-1 verification process.

What Phase1 requirements must be addressed in Sprint 2?

  1. https://wiki.duraspace.org/display/FF/Design+-+WebAccessControl+Authorization+Delegate#Design-WebAccessControlAuthorizationDelegate-ProposedRequirements(Phase1)

Proposed Sprint-2 Requirements

1. Include in sprint-2: Enforce ACLs...
2. Not high-priority, nice to have: Add ACL...
3. Include in sprint-2: Implement acl:Control...

4. Include in sprint-2: F4 MUST provide...

5. Include in sprint-2: Enforce ACLs on binary files
6. Include in sprint-2: More documentation
7. Not high-priority, nice to have: Support external ACLs...
8. Include in sprint-2: Add support for agentClass graphs defined within F4

9. Not high-priority, nice to have: Add support for agentClass graphs defined external to F4

10. Include in sprint-2: Verify header-based...

11. NOT in sprint-2: Support for inclusion of other ACLs via acl:include

12. Include in sprint-2: Fix bug with versioned resources
13. Include in sprint-2: Make webac and audit default configuration in fcrepo-webapp-plus

Developer Sprint-2 Planning Meeting

  1. 11am meeting on 10/26